Information we process
Sign-in provides an account identifier, display name, and email address. We store API key names, non-secret prefixes, verification hashes, permissions, and usage dates. We record purchased credits, payment references, refunds, and the financial ledger. Stripe processes card and payment details; FetchGoblin does not store full payment card numbers. Email signup and password recovery use one-time links. Passwords are stored as salted scrypt hashes; session and verification tokens are stored as verification hashes. Pending service emails are encrypted.
Request metadata includes the endpoint, time, status, latency, credit charge, and a request fingerprint. Request bodies and query parameters are sent to the configured data provider to retrieve your requested data. They are not stored in usage history. When you send an idempotency key, we temporarily store the response to safely replay it.
Purposes & legal bases
We process account and billing data to deliver the service and fulfill the agreement. We process security and operational records to protect accounts, investigate failures, and prevent abuse. Financial records are retained as needed for applicable accounting obligations. If consent is required for an additional purpose, we will request it before that processing.
Providers & transfers
Google supports optional Google sign-in using your verified identity, email address, and basic profile. Google access tokens are not retained. Oracle Cloud Infrastructure hosts the application, PostgreSQL database, and temporary response storage. Cloudflare provides DNS, HTTPS proxying, and edge protection. Stripe handles payments, invoices, and the billing portal. ScrapeCreators initially supplies the API data; Resend delivers requested verification and password recovery emails using your email address and a one-time link; providers may later vary by endpoint. These providers process information needed to deliver their services. International processing may occur; applicable transfer safeguards must be configured by the operator.
Retention
Request metadata is retained for up to 90 days. Idempotent response copies are retained for 24 hours and removed by scheduled housekeeping. These response copies may contain source-platform personal information, so request only data you are authorized to process. Financial and security audit records are retained separately for applicable accounting, dispute, and security needs. Account information remains while the account is active and as necessary to resolve outstanding obligations. Signup links expire after 24 hours and reset links after 30 minutes. Expired tokens and service-email copies are removed by scheduled housekeeping. IP addresses are used transiently for authentication protection; the shared rate limit stores keyed hashes for up to two hours, rather than raw IP addresses.
Cookies & analytics
Authentication uses essential session technology. When enabled, optional PostHog analytics is enabled by default for visitors identified outside the EU/EEA and UK using trusted hosting metadata, unless they opt out or send a Global Privacy Control signal. Visitors in the EU/EEA, UK, additional consent-required countries, or unknown locations must accept before analytics starts. Country-level hosting metadata is used only to choose this policy; location and raw IP addresses are not sent to PostHog. Analytics measures page visits, signup, key creation, checkout, credit purchases, and first successful requests. We use product-specific pseudonymous identifiers and short campaign tags. Email addresses, API keys, request parameters, scraped content, and payment details are excluded. Masked session replays help us understand navigation and usability. All text and inputs are masked; images, embedded frames, code, and API responses are blocked. Authentication and administrator pages are not recorded. Console logs, network headers and bodies, automatic click capture, and PostHog IP geolocation are disabled. Recordings use a first-party relay which checks the current analytics preference before forwarding data. Processing may take place in the configured US or EU PostHog region.
Your choice lasts 180 days. Use “Analytics settings” in the footer to turn analytics off or withdraw consent; collection stops and queued events are removed. Global Privacy Control declines analytics automatically. Events waiting for delivery expire after seven days; delivered events use PostHog Cloud in the United States. The current paid plan retains analytics events for seven years unless they are deleted earlier following a valid deletion request. Session replays are retained for 30 days under the PostHog project’s replay settings. Withdrawal does not erase data already delivered; contact the operator to request deletion. Essential billing, security, and service usage records continue independently of optional analytics preferences. A regional default stops when hosting metadata identifies a consent-required or unknown location. Saved opt-outs take precedence over regional defaults. FetchGoblin does not use these events for cross-site advertising or sell them to advertisers.
Your choices & rights
You can revoke API keys and export request history in the dashboard. Contact the operator to request account closure, access, correction, deletion, or other rights available under applicable law. Some records may need to be retained to satisfy legal duties or resolve disputes. You may complain to the relevant privacy regulator where that right applies.
Security & source data
Supplier and payment secrets stay on the server. FetchGoblin stores customer key verification hashes and uses access controls to isolate account records. No online service can guarantee absolute security. You control what you request and how you use the returned data; you remain responsible for your own downstream storage and processing.
Contact & operator
FetchGoblin is operated by Synosonic OÜ. Kaupmehe tn 7-120, Kesklinna linnaosa, Tallinn, Harju maakond, 10114, Estonia Estonian registry code 17459719
Contact [email protected] for support, privacy requests, billing questions, and abuse reports.